[00:01.120 --> 00:07.280] I think I'll make a two bottle, who you know, still won't pay out, I'm only doing my thing up. [00:10.980 --> 00:13.680] Oh god, no, no. [00:14.200 --> 00:14.600] Tulip. [00:15.460 --> 00:16.800] Tulip for... [00:16.800 --> 00:17.300] Tulip. [00:18.160 --> 00:20.480] What, you mean conventional, um, proax? [00:20.720 --> 00:20.820] No. [00:21.120 --> 00:21.380] Right. [00:21.660 --> 00:21.860] Normal. [00:24.940 --> 00:25.740] Okay, um... [00:28.080 --> 00:33.840] Because at the moment, yeah, the picture quality is going to be absolutely rubbish, if we're looking at this, looking through that, and looking through another camera. [00:34.280 --> 00:34.980] It's going to be crap. [00:35.200 --> 00:35.300] Okay. [00:39.560 --> 00:40.260] Pass it down. [00:40.580 --> 00:40.900] What do you say? [00:41.560 --> 00:42.000] Operator. [00:49.850 --> 00:55.170] Um, the next item has not started yet in New York. [00:55.810 --> 00:57.970] So, we're waiting for them to start. [01:18.460 --> 01:20.320] Save that one until a little bit later. [01:24.680 --> 01:24.720] Good sir. [01:43.360 --> 01:43.880] Yeah. [02:17.310 --> 02:18.470] Are we all hooked up? [02:21.410 --> 02:22.370] Okay, we're set? [02:22.750 --> 02:23.830] Oh, all right. [02:26.270 --> 02:33.070] Greetings, those that are still awake and not completely chemically intoxicated out in the other room hacking into every other box that's coming up on the network. [02:34.110 --> 02:35.890] We are The L0pht. [02:35.990 --> 02:37.510] You can get to us at l0pht.com. [02:38.150 --> 02:40.190] Some of you have heard of us, some of you might not have. [02:40.910 --> 02:42.730] We're going to be talking to you today for an hour. [02:42.870 --> 02:50.010] We're going to do our best to keep it directly at an hour because I know everybody's anxious to get on to the next things and we're being followed by Bruce Schneier, which is fucking rad. [02:53.810 --> 03:14.860] What we're going to talk about here today is we're going to give you a brief background on the L0pht, on why we're there, what we're doing, why companies should stop persecuting us, that we're helping everybody, and that hackers are probably the best thing that America has going for it right now. [03:16.180 --> 03:16.900] Damn straight. [03:17.440 --> 03:25.060] We're going to run through the different members, introduce them, because a lot of people know probably me more than the other people in the L0pht, and that's not how the L0pht works. [03:25.080 --> 03:27.360] By any means, I just happen to be a media whore. [03:28.060 --> 03:42.860] And we're going to run through, talk about some of the different projects that are going on, and at the end, if we have time, I'm going to just fly you through The L0phtCrack presentation slides on why you should not trust Microsoft crypto, because we've gotten enough requests for it. [03:42.860 --> 03:48.340] So let me go into the background on what the L0pht is, and what we're kind of doing out there. [03:49.340 --> 04:02.380] The best description I've gotten of the L0pht, other than goddamn motherfucking hackers breaking into systems, don't let them date your daughters type ordeal, is a consumer watch group. [04:02.380 --> 04:07.360] And somebody said that to me, and I said, okay, I guess. [04:08.440 --> 04:15.720] People are selling you stuff, people are selling the companies that you work for, products and solutions, and they're going, just trust us. [04:16.020 --> 04:16.820] Well, why? [04:17.860 --> 04:18.960] Because it's secure. [04:20.220 --> 04:21.520] Why is it secure? [04:22.340 --> 04:23.860] Because we say so. [04:24.880 --> 04:26.240] No, wrong answer. [04:27.780 --> 04:34.480] The advisories page that went up a little while ago has been some exploit stuff that goes around as we find them. [04:34.680 --> 04:37.560] We tried to originally contact most of the vendors about them first. [04:37.820 --> 04:39.980] The vendors really didn't care. [04:40.260 --> 04:45.540] They came back to us, one large company in Massachusetts, who does one-time passwords. [04:46.700 --> 04:48.740] Actually, we approached them about a year ago. [04:49.320 --> 04:50.940] Probably about two years ago now. [04:51.440 --> 04:54.960] And we said, we've found a whole bunch of flaws in your product. [04:55.260 --> 04:58.760] And anybody using your cards is at risk. [04:58.860 --> 04:59.720] Do you know of these flaws? [04:59.840 --> 05:00.940] And they said, we don't have any flaws. [05:02.380 --> 05:04.060] So we sent them packet dumps. [05:04.060 --> 05:10.760] And we showed us breaking into systems that we had legitimate access to do this to, saying, you still have these flaws. [05:10.800 --> 05:11.660] Do you believe us now? [05:11.900 --> 05:13.120] And they said, oh, wow. [05:14.340 --> 05:16.360] How many of our customers know about this? [05:17.740 --> 05:18.720] I said, I don't know. [05:18.840 --> 05:20.560] If we found it, anybody else could find it, too. [05:20.760 --> 05:21.940] We didn't go tell your customers. [05:21.960 --> 05:22.600] We went to you. [05:23.120 --> 05:24.460] I said, ah, good. [05:26.300 --> 05:27.980] They refused to do anything about it. [05:28.080 --> 05:30.720] They kept telling their customers that there weren't any problems and everything. [05:30.780 --> 05:42.940] So we gave up on that track, and now we basically posted so that the bad guys, the good guys, the whatever, the bad guys being the companies, the good guys being the hackers, get access to this stuff at the same time. [05:42.940 --> 05:48.480] And all of a sudden, their customers start complaining, and that makes the companies stop and fix things. [05:48.680 --> 05:50.560] So that's the gist behind the advisories page. [05:50.760 --> 06:01.760] We've had a long history in the hacking underground with the old CDC and ATDT and great freaking Boston boys that later go out to the West Coast, whatever. [06:03.480 --> 06:04.040] Traitors. [06:04.040 --> 06:04.080] Traitors. [06:06.820 --> 06:08.220] Okay, it is a little warmer, yeah. [06:09.740 --> 06:15.740] We have the old Black Crawling Systems Archives, which is a bulletin board run by Brian Oblivion for a long time. [06:16.140 --> 06:17.240] Big piece of history. [06:18.660 --> 06:19.460] CDC stuff. [06:21.060 --> 06:21.860] Just amazing. [06:23.320 --> 06:25.960] And we try and keep a decent repository up there. [06:26.340 --> 06:29.600] Other things that we're doing is R&D on the hardware side of things. [06:29.600 --> 06:33.040] We have a really decent hardware group inside the L0pht. [06:33.140 --> 06:36.740] And I think that's one of the things that really spreads us apart or splits us apart from other things. [06:37.100 --> 06:42.180] We've got Brian Oblivion and Kingpin over there are just the freaking whizzes when it comes to smart cards. [06:43.400 --> 06:46.000] POCSAG decoder kits, maybe you've seen some of those things. [06:46.460 --> 06:52.400] I guess there was some red box toll fraud detection unit schematics that Kingpin came up with. [06:52.480 --> 06:53.640] I thought that was kind of ironic. [06:57.720 --> 06:59.200] And then we come out with tools. [06:59.320 --> 07:00.580] We like to give back to the community. [07:01.620 --> 07:06.040] A lot of people have come up to us and said, well, you know, what is the L0pht offering us? [07:06.360 --> 07:09.580] And on the cover on the front, it's like, well, geez, you can get a shell account here. [07:09.660 --> 07:10.880] You can get a web page here. [07:11.640 --> 07:13.600] Or, you know, you can get an email address here. [07:15.040 --> 07:16.360] That's not the reason behind it. [07:16.940 --> 07:19.320] The thing is we pay for this thing entirely out of our pockets. [07:19.700 --> 07:20.360] We don't mind. [07:20.480 --> 07:21.080] We like it. [07:21.160 --> 07:22.140] This is something we love doing. [07:22.140 --> 07:25.880] We will always be doing this thing until they throw us behind bars, which hopefully they won't do. [07:26.560 --> 07:28.200] Because we're not doing anything wrong. [07:30.300 --> 07:35.960] And if you've ever seen PBS, and PBS says, you know, send us in $50 and we'll send you back a bumper sticker. [07:36.480 --> 07:38.460] You're not spending $50 for the bumper sticker. [07:38.500 --> 07:41.880] You're plugging it back in to keep the L0pht up and running to try and give back to the community. [07:42.400 --> 07:43.400] Eh, you want to do it, great. [07:43.520 --> 07:45.120] If not, all the stuff is always up there. [07:45.200 --> 07:45.960] We'll always be free. [07:47.140 --> 07:50.420] With that, I'm going to start going through a little introduction of the people. [07:50.420 --> 07:53.300] And then I'm going to let each of them talk for a few minutes. [07:53.460 --> 08:01.260] And if we have time, Weld, the co-author of L0phtCrack, and I are going to whip through the L0phtCrack presentation on how to beat Microsoft crypto. [08:01.860 --> 08:04.760] So, without further ado, let me start running down the line here. [08:06.520 --> 08:11.560] Just briefly by names and then you want to go on into your actual talks or do you want to... [08:11.560 --> 08:12.100] Sure, yeah. [08:12.260 --> 08:12.860] Take it that way. [08:13.020 --> 08:13.120] Okay. [08:13.120 --> 08:14.220] Far left, Mr. Brian Oblivion. [08:18.960 --> 08:19.360] Hi. [08:19.740 --> 08:23.040] You probably mostly know me from the Black Crawling Systems. [08:24.360 --> 08:27.960] It's just something I sort of kept going after I ran the BBS. [08:28.860 --> 08:31.000] I get a lot of mail saying the links are broken. [08:31.400 --> 08:32.360] Please fix this. [08:34.200 --> 08:36.940] I really need to talk to some people who are having problems with that. [08:37.120 --> 08:38.720] Because when I try it, it works fine. [08:40.580 --> 08:42.840] And I think most of it is coming from AOL. [08:43.040 --> 08:44.580] But I really want to fix this. [08:44.780 --> 08:47.200] So, send me some e-mail. [08:48.100 --> 08:50.280] Or talk to me after the show. [08:50.280 --> 09:01.660] So, the other hardware projects that I'm working on, and this is why black crawling systems mostly gets pushed to the side, is Joey and I mostly work on hardware projects together. [09:03.060 --> 09:13.140] And we're working on a universal decoder to decode not only POCSAG, which that original public domain circuit did quite well for how simple it was. [09:13.140 --> 09:21.540] We want to come up with something along the lines as the, I think it was the Radio Electronics article did with a PIC chip. [09:21.900 --> 09:31.940] But I think we're going to need something a little more powerful than a PIC chip to decode FLEX-Reflex, which is the two-way paging protocol that Motorola is coming out with. [09:32.540 --> 09:40.440] And we'd also like it to do Mobitex, some artist stuff, as well as the police MDT decoders. [09:42.400 --> 09:49.000] Aside from that project, I'm also working with some other hackers up in the Boston area on a group called BAUSIG. [09:49.140 --> 09:52.940] It's the Boston Wireless Signal, I'm sorry, Special Interest Group. [09:53.640 --> 10:02.100] And we're trying to put together a free wireless network for most of the underground. [10:02.600 --> 10:05.720] And we're having trouble trying to establish nodes. [10:06.260 --> 10:09.740] And the other problem is the stuff costs dollars, and we don't have a lot of dollars. [10:12.140 --> 10:23.700] We're mainly in the R&D phase right now, and we're trying to network with other people to hopefully set up some points of presence across the United States once we grow it past the R&D phase. [10:24.700 --> 10:29.620] Right now I'm working with Doctor Who, Tom Icom, BW, and Method. [10:30.680 --> 10:32.620] And they've really helped a lot. [10:33.020 --> 10:36.660] And it probably wouldn't be where it is today if it was just me and Joe. [10:37.320 --> 10:38.560] And Weld, actually. [10:41.060 --> 10:42.600] I think that's about it. [10:43.280 --> 10:44.500] I'll move it over to Joe. [10:44.620 --> 10:47.120] He can talk more about our pilot hacks. [10:48.480 --> 10:49.420] The U.S. Robotics Palm Pilot. [10:49.720 --> 10:52.540] I see a lot of people in the audience using these things. [10:52.680 --> 10:54.560] I think it's a pretty hot ticket. [10:54.760 --> 10:59.980] And we're going to come up with some sort of hacking tools for the Palm Pilot. [11:00.840 --> 11:01.320] Joe. [11:05.800 --> 11:06.280] Hi. [11:07.200 --> 11:08.100] I'm Kingpin. [11:08.260 --> 11:12.400] I'm one of the guys doing the hardware development and embedded system stuff. [11:13.120 --> 11:15.500] As Brian said, we've been working with the U.S. [11:15.540 --> 11:17.860] Robotics Palm Pilots for a little bit. [11:18.000 --> 11:19.680] Just playing around with them, getting a feel for them. [11:19.880 --> 11:25.700] If nobody's ever seen them before, you should look in any electronics magazine and you'll see an article about them. [11:25.740 --> 11:27.940] Or you can look up here and see this. [11:29.180 --> 11:36.060] As a general overview, the pilot is based on a Motorola Dragon Ball processor, which is a 68,000 family. [11:36.800 --> 11:39.300] And it's developed specifically for PDA use. [11:39.540 --> 11:40.620] And it's very powerful. [11:40.620 --> 11:42.140] It's clocked at 16 megahertz. [11:43.740 --> 11:53.520] And it has glueless interface to PCMCIA, external POCSAG and Flex decoding ICs, infrared communications, and LCD display. [11:53.620 --> 11:57.980] So it's a really powerful chip, which makes it attractive to hack with. [11:59.800 --> 12:01.920] And we chose the pilot for a number of reasons. [12:01.980 --> 12:03.960] Because it's small and it's low cost. [12:04.080 --> 12:05.480] And a lot of people seem to have them. [12:05.860 --> 12:09.480] And as I said, the hardware design is really great for hacking. [12:11.860 --> 12:22.160] There's two areas that we're going to modify on the pilot, which allow easy access to the Dragon Ball internals without having to rip open the pilot and play with all the surface mount stuff. [12:22.300 --> 12:31.500] There's the hot sink connector on the bottom, which you use to hook up to the desktop machine and the modem to transfer your data. [12:31.500 --> 12:33.180] And there's also a memory slot in the back. [12:33.380 --> 12:35.680] So that's how we'll do a lot of our modifications. [12:37.560 --> 12:39.260] Basically, I'm just going to run through these real quick. [12:39.560 --> 12:42.800] The first is infrared and low speed wireless communications. [12:43.700 --> 12:53.940] We're going to have some probably just point to point or maybe just a wireless way to hot sync your data so you don't always have to be connected to a desktop machine. [12:53.940 --> 12:59.060] And important tools that we're hoping on doing is some network security auditing tools. [12:59.400 --> 13:08.920] And basically, we want to turn the pilot into a very portable auditing tool, which would allow network sniffing and maybe some basic vulnerability probing. [13:10.100 --> 13:14.300] So something easy we can just hook up to the network and see what's going on. [13:15.140 --> 13:18.660] Another one is pilot to pilot communications, which is something that U.S. [13:18.740 --> 13:21.660] robotics never put into their plan for some reason. [13:21.820 --> 13:25.700] We can exchange data back and forth and either with infrared or through a cable. [13:25.980 --> 13:29.440] So Brian and I could trade memos or wares or whatever we want to do. [13:29.560 --> 13:29.780] I don't know. [13:32.340 --> 13:41.720] And the final project is part of what Brian said, using the universal decoder for the POCSAG and Flex and the mobile data terminal stuff. [13:42.920 --> 13:49.180] Basically, just plug it in right through the bottom and have the serial interface and that would be good. [13:50.020 --> 13:56.080] And basically, the beauty of the pilot hacking is that it involves everybody in the L0pht because of the hardware and software side of things. [13:56.100 --> 14:02.360] So we can all work together and work on a communal project and put it out to you guys and hopefully something good will come of it. [14:02.680 --> 14:04.500] So that's about it. [14:04.780 --> 14:09.740] Hey Kingpin, can you tell them exactly what the POCSAG and Flex decoding in the Palm pilot will let them do? [14:09.740 --> 14:13.600] I'm sure there are a lot of people out there that aren't exactly aware of what POCSAG and Flex necessarily are. [14:13.860 --> 14:14.260] All right. [14:14.400 --> 14:17.800] Well, basically, POCSAG and Flex are two paging protocols. [14:18.040 --> 14:21.600] And in, I don't know, there's POCSAG decoder software out there. [14:21.660 --> 14:31.540] We had a kit that we sold and it basically allows you to just receive the data transmissions with a scanner and hook it up to the decoder and basically monitor all pager transmissions. [14:31.540 --> 14:44.020] And some people on the net released some software for mobile data terminals, which are the police terminals in the cars, in the police cars, which you can watch NCIC database accessing and things like that. [14:44.100 --> 14:46.480] And that's become a pretty hot topic. [14:46.680 --> 15:05.940] So using the pilot, which has very good support for the POCSAG and Flex decoder ICs, which Motorola also makes, we can hopefully do something with that, which will basically just plug the radio in maybe and receive pages on the pilot instead of on a laptop or a big desktop machine. [15:07.040 --> 15:08.060] Or on the pager. [15:08.860 --> 15:09.340] What? [15:09.580 --> 15:10.040] Oh. [15:10.140 --> 15:11.880] And we can use the pilot as a pager, too. [15:12.320 --> 15:13.220] That's a lame part. [15:14.880 --> 15:15.360] That's it? [15:15.480 --> 15:16.160] That's it. [15:16.360 --> 15:16.640] That's it. [15:16.640 --> 15:16.640] Thanks. [15:17.380 --> 15:18.260] Mr. Space Rogue. [15:24.140 --> 15:26.580] I'm Space Rogue and I'm a Macintosh user. [15:31.160 --> 15:35.300] One of the big things I do at the L0pht are a couple of things. [15:35.900 --> 15:37.840] One's a bunch of hardware hacks I have. [15:37.940 --> 15:39.360] Some of you may have seen my pages or not. [15:40.460 --> 15:44.440] Basically modifying Apple's hardware into doing stuff that they didn't think it could do. [15:45.080 --> 15:45.940] Perverse things. [15:45.940 --> 15:48.540] Putting green tubes and Mac pluses, that sort of thing. [15:48.860 --> 15:50.720] But that's one thing I do. [15:50.840 --> 16:02.080] Another thing I do, I'm going to keep this real short, is I administer the Whacked Mac Archives FTP site, which is basically a very large collection of Macintosh hacking tools. [16:03.720 --> 16:13.900] Prior to this site going up about, I don't know, three years ago, it was very difficult to find war dialers or other types of tools for hacking on a Macintosh. [16:14.580 --> 16:20.280] So one of the things I did is I put all the files that I had and I had collected over the years into a big FTP site. [16:20.440 --> 16:22.440] When it started out, it was like 20 megs. [16:22.600 --> 16:24.280] You know, whole lots of Macintosh hacking tools. [16:24.940 --> 16:27.560] It's now grown to about 80 megs, 90 megs. [16:29.120 --> 16:31.560] And all the files are available free. [16:32.080 --> 16:33.420] We don't charge for them. [16:33.760 --> 16:34.440] They're there. [16:34.620 --> 16:35.620] They're mostly shareware. [16:35.620 --> 16:38.420] It's all legal software that you can own. [16:38.960 --> 16:40.580] There's no commercial stuff on it. [16:40.660 --> 16:43.200] And I get e-mail all the time, people asking, where are the wares? [16:43.940 --> 16:46.280] It's just the hacking tools that are there. [16:47.940 --> 16:51.200] The FTP site was very popular when it first started. [16:51.500 --> 16:53.400] And it kind of sucked all our bandwidth down. [16:53.680 --> 16:56.760] So we had to limit the number of users that could get into it. [16:57.600 --> 17:02.660] As a result of that, one of the things I did, or we did, is we published a CD. [17:03.300 --> 17:09.240] The CD contains all the files that were on the website back in November last year. [17:11.080 --> 17:18.440] That is to allow people who didn't want to wait in line for the five-user FTP site to just buy the CD and get all the same files. [17:19.280 --> 17:27.900] And as it was proved out to be very popular, it put a lot of money into the L0pht that we could use to pay our ISDN bill, our electric bill, our heating bill, etc. [17:28.200 --> 17:28.420] Rent. [17:28.980 --> 17:30.000] Stuff's rather expensive. [17:30.000 --> 17:32.260] So, we're thinking about Whacked 2. [17:32.440 --> 17:33.200] It may or may not appear. [17:34.500 --> 17:39.720] The other things that I'm working on in conjunction with Stefan are banging on some Apple software. [17:40.400 --> 17:45.200] Specifically, the new software, AppleShare IP was just recently released and whatnot. [17:45.360 --> 17:46.420] I'll let Stefan go into that. [17:46.960 --> 17:49.900] But that's where we're looking at software-wise. [17:50.140 --> 17:51.480] There are holes in AppleTalk. [17:51.800 --> 17:53.000] You just need to find them. [17:53.540 --> 17:57.760] As soon as we get some repeatable ones that we can write up, they will be on the advisory pages. [17:58.300 --> 18:01.840] And with that, I'll turn it over to Stefan to talk more about the Macintosh software stuff. [18:02.460 --> 18:02.600] Thanks. [18:08.060 --> 18:10.800] I'm Stefan, and I'm the other token Mac user. [18:11.040 --> 18:14.200] I think two people out of seven is a pretty high percentage of Mac people. [18:14.420 --> 18:14.980] We've met quota. [18:15.340 --> 18:16.900] Yes, we've more than met quota. [18:17.540 --> 18:30.040] I try to cross over between the hardware and the software because I'm responsible for the infrastructure, power distribution, network topology, our backbone in our loft site, the other type of loft, L-O-F-T. [18:30.560 --> 18:33.660] Our PBX, which we trashed and repaired. [18:34.120 --> 18:37.800] And I also keep up the L0phtEye, our live video feed out. [18:38.680 --> 18:43.120] To keep this brief, to keep this down so we can get on to people. [18:43.400 --> 18:44.620] I just want to touch on some main points. [18:46.100 --> 18:49.920] Don't underestimate the power company for data transmission. [18:50.200 --> 18:59.560] Everyone's getting all hyped up about the regional Bell operating companies having competition now from the cable facilities, cable modems, oh boy. [18:59.560 --> 19:02.480] But people are overlooking the power company. [19:02.800 --> 19:04.760] Power cabling goes into every facility. [19:05.260 --> 19:10.560] Right now you can get 14, 4K over conventional power lines into any house. [19:10.740 --> 19:14.080] And it's a shared medium just like the cable modems are. [19:14.260 --> 19:16.500] But with one advantage to the hacker. [19:16.880 --> 19:22.220] Where the cable company can slap a TDR on your line and find if you've tapped into the cable line. [19:22.420 --> 19:26.020] Electric company, there's no way to monitor any taps on the electric line. [19:26.160 --> 19:28.480] It's just as if you were plugging in a toaster. [19:28.480 --> 19:33.280] So with data transmission, it's going to be picking up over electric lines. [19:33.400 --> 19:34.080] That's something to watch. [19:34.200 --> 19:37.680] That's going to be a huge outlet for focusing hacking resources on. [19:38.080 --> 19:40.100] The next issue, of course, is Apple. [19:40.680 --> 19:43.580] Traditionally, Apple has been focused on AppleTalk protocols. [19:43.800 --> 19:45.420] Great for local area networks. [19:46.260 --> 19:49.060] Of course, AppleTalk is not what's traversing the Internet. [19:49.400 --> 19:54.300] But Apple's products now are breaking out for the first time into Internet protocols. [19:54.300 --> 20:02.960] Their AppleShare IP, which had been traditionally just an AppleShare using AppleTalk protocol, is now bringing on TCPIP. [20:03.320 --> 20:06.140] There may be vulnerabilities there, which Apple's not aware of. [20:06.300 --> 20:10.440] Not a lot of focus has gone on to Apple's AppleShare IP product. [20:10.440 --> 20:19.120] So we need to focus a lot of collective... I mean, our... the L0pht and as well as the community hacking efforts on AppleShare IP. [20:19.420 --> 20:21.460] It's got a well-known port. [20:21.640 --> 20:25.820] If you run a port scanner against an AppleShare IP server, it will be a very specific ID. [20:26.460 --> 20:33.460] Up until AppleShare IP was released, the only open port on the Apple IP stack was for ICMP ping. [20:33.460 --> 20:38.260] So you can not only identify a Mac that's sitting with nothing running except for the IP stack. [20:38.480 --> 20:42.980] But you can identify, with a single port on a scan, the AppleShare IP server. [20:43.620 --> 20:48.780] The other product besides the AppleShare IP server is the Apple Network Admin Toolkit. [20:49.120 --> 20:51.040] Existing product out for about a year and a half. [20:51.260 --> 20:54.560] They've just gone to version 2.0, integrating TCPIP. [20:55.160 --> 20:59.280] All of my information is that the version 2 has been rather slapped together. [20:59.440 --> 21:02.720] That they've integrated IP into this product without a lot of testing. [21:02.960 --> 21:05.560] Just to add functionality over a WAN connection. [21:06.120 --> 21:07.560] Again, it's a well-known port. [21:08.520 --> 21:10.320] It'll show up on a port scan very easily. [21:10.840 --> 21:16.180] And on the Apple Admin Network Admin Toolkit, passwords are stored in a central registry. [21:16.520 --> 21:20.920] Akin to the way UNIX system is going to have a password file encrypted. [21:20.920 --> 21:29.780] If on Apple Network Admin Toolkit, if you can grab the central password registry, you've got admin control, not only over that box, but over the network. [21:30.460 --> 21:36.780] Just in summary, watch Apple because their products don't have a lot of focus right now from the hacker community. [21:36.980 --> 21:42.600] And I think that's going to be allowing them to slip in some vulnerabilities that we need to find. [21:44.540 --> 21:52.620] The investment from Microsoft just recently, the millions that was put into Apple, coupled with the business pressure that's on Apple right now. [21:53.540 --> 22:00.540] This Microsoft investment, it might be something more than just trying to get Internet Explorer pre-installed on Macs. [22:00.660 --> 22:05.220] We may see some NT login authentication coming to a Mac OS system. [22:05.500 --> 22:09.360] And I'll leave it to Mudge to point out of the obvious things of why that is going to be a problem. [22:09.560 --> 22:11.920] But don't overlook Apple for security holes. [22:12.060 --> 22:12.900] They're going to be coming up. [22:20.340 --> 22:22.200] Hi, I'm Weld Pond. [22:22.440 --> 22:24.240] And I'm in the software group. [22:24.440 --> 22:28.420] And I mostly concentrate on keeping the website up, the content there. [22:28.560 --> 22:31.880] I'm responsible for those ugly graphics that some people complain about. [22:32.060 --> 22:34.820] But I'm not a graphic artist. [22:38.180 --> 22:43.640] And more importantly, recently, I've been working closely with Mudge on L0phtCrack. [22:43.640 --> 22:50.760] And trying to put my expertise in writing interface code to make something that's... [22:50.760 --> 22:53.640] Well, we talk about, you know, tools kitties. [22:53.820 --> 23:07.360] But unless you make something that anyone can use, that any reporter can look at, that any marketing person at Microsoft can actually download and use themselves, then they're not going to think these holes actually exist or are a threat. [23:07.360 --> 23:14.860] They just think it's an obscure problem that maybe a couple hackers might exploit. [23:15.300 --> 23:36.160] But if you make something easy to use, and I recommend this to anyone who has an exploit script or has something written down as an exploit, if you have the capability or you don't, find someone to write an interface on it and give it a good name and you'll get press. [23:38.600 --> 23:39.660] Microsoft hates that. [23:39.740 --> 23:41.080] And Microsoft hates that. [23:41.360 --> 23:42.680] And that's why we love that. [23:45.740 --> 23:50.260] The advisories page has become something important for us. [23:50.340 --> 23:56.700] We've actually had people contacting us, asking us whether they can release things on our advisories page. [23:57.040 --> 23:58.140] Of course you can. [23:58.280 --> 23:59.540] And we would like you to do that. [23:59.540 --> 24:06.700] We've sent things out to CERT, things to Sun Security Group, things to the Microsoft, the Secure at Microsoft mailing list. [24:06.960 --> 24:08.780] And it's kind of a black hole. [24:09.240 --> 24:11.460] No one knows what you sent them. [24:11.500 --> 24:13.880] No one in the rest of the hacker community knows about these things. [24:14.040 --> 24:15.000] They just go away. [24:15.240 --> 24:18.120] And sometimes they pop up, sometimes they don't. [24:18.280 --> 24:20.560] Usually when they pop up, you don't get any credit for it. [24:22.000 --> 24:27.980] If you put something on the L0pht advisories page, of course you'll get prominent credit for it. [24:27.980 --> 24:29.520] You put it on the mailing list. [24:29.740 --> 24:32.420] We don't need things like CERT to get the information out there. [24:32.420 --> 24:33.280] Yeah. [24:37.260 --> 24:39.200] So that's really all I have to say. [24:39.720 --> 24:41.000] So I'll have to Tan. [24:45.980 --> 24:46.820] I'm Tan. [24:46.980 --> 24:49.380] And I don't have a whole lot for you here. [24:49.540 --> 24:52.320] I'm working on Netware and NDS. [24:52.580 --> 24:54.960] I don't have anything ready at this point. [24:55.520 --> 24:58.960] I'd also like to point out that I'm handling the merchandise. [24:58.960 --> 25:03.000] And there are a few problems with it. [25:03.100 --> 25:10.700] So if anyone here has a check that's been cashed for merchandise and hasn't received that merchandise yet, we are working through some problems with the supplier. [25:10.740 --> 25:13.220] So just bear with us for a little while. [25:13.280 --> 25:16.560] We know you're out there if your check has been cashed. [25:19.520 --> 25:21.780] Can we kick the PowerPoint slide on now? [25:26.120 --> 25:28.520] Will the guys that hit be able to see the PowerPoint stuff? [25:31.420 --> 25:33.460] Because I don't know if some of it's exportable. [25:35.820 --> 25:36.620] Oh, okay. [25:36.820 --> 25:39.280] Well, I didn't know anything. [25:39.460 --> 25:48.940] Before I go on on this, let me take this opportunity to mention another project that's going on that is really quite kick-ass. [25:49.700 --> 25:52.300] We've got Theo du Raadt sitting around somewhere in the back. [25:52.300 --> 25:56.900] And Theo is probably the prominent head of the OpenBSD project. [25:57.360 --> 25:59.080] I don't know how many people have heard of this. [25:59.160 --> 26:00.300] How many people are familiar with it? [26:01.420 --> 26:02.300] OpenBSD rocks. [26:03.880 --> 26:04.820] Theo is over here. [26:04.960 --> 26:06.800] He's got a bunch of the CDs for OpenBSD. [26:07.160 --> 26:11.300] OpenBSD is a BSD-derived UNIX with... [26:12.020 --> 26:15.220] Theo, how many security enhancements right now over NetBSD? [26:19.280 --> 26:19.720] Thousands. [26:19.720 --> 26:20.740] Thousands. [26:22.660 --> 26:23.780] This is... [26:23.780 --> 26:29.420] And Theo is probably going to slap me silly for saying this, but this is largely an operating system written by hackers. [26:30.060 --> 26:32.080] By serious hackers. [26:32.360 --> 26:34.220] And there is some good shit inside here. [26:35.500 --> 26:36.360] Where are you, Theo? [26:36.900 --> 26:38.440] Like our fork, right? [26:41.440 --> 26:47.980] Anyway, anybody who wants to contribute to the cause of OpenBSD should stop by, see Theo, see anybody carrying around a large stack. [26:48.220 --> 26:55.160] This has like the L0pht seal of approval, which since this one does have our fork in it, it's kind of like signing bad code, you know, signing malicious applets. [26:55.300 --> 26:55.560] I don't know. [26:56.440 --> 26:57.280] I'm just kidding. [26:59.540 --> 27:00.980] Find somebody carrying this around. [27:01.260 --> 27:01.780] Pick it up. [27:02.080 --> 27:03.680] If you run Linux, you're going to love this. [27:03.840 --> 27:06.520] If you're running NetBSD or FreeBSD, you're going to love this. [27:06.520 --> 27:07.900] You'll never go back. [27:08.820 --> 27:11.180] And now let's kick into L0phtCrack. [27:11.340 --> 27:13.080] This is a talk I've given at a couple places. [27:14.100 --> 27:16.400] Gave this to Microsoft a little while ago. [27:16.460 --> 27:18.180] They weren't tremendously happy about it. [27:20.440 --> 27:21.640] But that's okay, right? [27:22.340 --> 27:26.580] This is going to be a little awkward because I'm going to try and point backwards. [27:26.900 --> 27:27.460] Let me... [27:27.460 --> 27:28.720] A little modifying hacking here. [27:35.810 --> 27:36.970] Oh, there you go. [27:37.230 --> 27:37.750] Look out. [27:38.210 --> 27:39.510] He hasn't even drank any beer. [27:39.510 --> 27:40.970] Oh, this is a little bizarre. [27:42.010 --> 27:42.530] All right. [27:42.770 --> 27:42.970] Okay. [27:44.890 --> 27:45.610] L0phtCrack. [27:46.010 --> 27:47.690] Why not use Microsoft passwords? [27:49.230 --> 27:54.010] First off, I can't stand working with Microsoft and I've gotten this label of like being an NT hacker. [27:54.170 --> 27:55.010] I don't like that. [27:55.470 --> 27:58.470] I don't want to be working on Microsoft products right now. [27:58.570 --> 27:59.870] The problem is they're everywhere. [28:00.730 --> 28:02.290] You cannot get away from them. [28:02.490 --> 28:06.430] You know, once in a while I take a job to like put some food on the table and everybody's going... [28:06.430 --> 28:16.130] Well, yeah, sure, we've got a couple of UNIX boxes over there, but those are those old gnarly UNIX gurus sitting back there and they don't talk to us and they smell and they don't sleep and they don't shower. [28:16.370 --> 28:16.510] And... [28:16.510 --> 28:20.050] But look at our nice sales marketing droids running this huge NT installation. [28:20.370 --> 28:21.790] See, aren't they pretty and sweet smelling? [28:23.910 --> 28:25.010] My ass is beautiful. [28:26.110 --> 28:29.390] Um, so at some point we had to start looking at Microsoft. [28:29.610 --> 28:37.730] And I know Hobbit, who's sitting around here, who's also a wealth of knowledge on Microsoft and at the same time is in the same boat as I am not wanting to be working on that. [28:37.730 --> 28:42.310] We like hacking UNIX instead runs into the same problem. [28:42.570 --> 28:46.250] So we were looking at how Microsoft was storing the passwords. [28:46.910 --> 28:59.150] Microsoft has the passwords hidden in the SAM registry and Jeremy Allison along with the help of somebody else, I'm just trying to remember names here, figured out a way of deobfuscating the password hashes in there. [28:59.150 --> 29:02.510] Now, there are two password hashes for each user. [29:02.590 --> 29:07.290] There's the land man hash and the NT which is derived off of MD4 one way function. [29:08.330 --> 29:09.070] Next slide please. [29:10.010 --> 29:12.910] So after deobfuscation of the registry, here's what you end up seeing. [29:13.150 --> 29:19.670] So we have a user who's got a username of two under bar A and it ends up not being a clever name because we're going to see his password as two A's. [29:20.090 --> 29:22.190] Um, UID is stored in there. [29:22.290 --> 29:23.070] You see that in the second field. [29:23.150 --> 29:27.110] This is almost like a UNIX /etc/password file or, you know, whichever NICs you're looking at. [29:27.110 --> 29:33.770] Now, the first hash ends up being the land man hash and the second hash ends up being the NT hash and we see them broken up down in the bottom. [29:34.030 --> 29:39.750] And I know I'm kind of flying through this a little bit but I gotta put like a 45 minute presentation into like 20 minutes here. [29:40.010 --> 29:43.550] So Weld and myself will answer questions afterwards. [29:44.070 --> 29:44.670] Get the next slide? [29:45.890 --> 29:53.790] Okay, the trick is land man is an older password scheme used for the Windows for Workgroup clients for Windows 95, 3.1. [29:53.790 --> 29:56.070] And of course NT has to understand this. [29:56.830 --> 30:02.390] There are some interesting little caveats to what you can do with a land man password. [30:02.770 --> 30:05.770] For instance, the passwords can be no more than 14 characters in length. [30:06.090 --> 30:07.010] Well, that's not bad. [30:07.130 --> 30:09.310] Your UNIX password can only be eight characters in length. [30:10.110 --> 30:11.890] So Microsoft's got one up on you right there. [30:12.530 --> 30:15.150] If the length is greater than 14 characters, it's truncated. [30:15.250 --> 30:18.650] If the length is less, it's padded out with nulls up to the 14th character. [30:19.190 --> 30:19.770] Next one. [30:22.030 --> 30:22.450] Okay. [30:23.230 --> 30:25.210] The password's converted to all uppercase. [30:25.490 --> 30:27.490] Well, they kind of lose on UNIX on that one. [30:29.030 --> 30:33.270] The 14-byte string, once it's converted to uppercase, ends up being split into two halves. [30:33.450 --> 30:36.110] And you've got, you know, seven characters and seven characters. [30:36.530 --> 30:39.530] Password's less than seven characters or equal to. [30:39.830 --> 30:41.670] The right-hand side is going to be all nulls. [30:42.310 --> 30:47.190] They take this and they derive an odd parity eight-byte DES key from each seven-byte half. [30:47.790 --> 30:48.150] Okay. [30:48.290 --> 30:48.910] Next slide. [30:50.750 --> 30:57.790] Now they take a known constant that they always use over and over and over again to encrypt each side. [30:58.630 --> 31:01.470] The two sides are then concatenated to form the land man hash. [31:01.630 --> 31:08.750] So your 14-character long password has now been turned down to a seven-character long password on each side that's only uppercase. [31:09.570 --> 31:12.150] Oh, and there's also no salt done to this. [31:12.890 --> 31:29.770] And the salting in UNIX when you actually look at the first 256 bits of the UNIX password is basically a randomization so that if you have the password of love and somebody else has the password of love and you look through the /etc/passwd file, it doesn't end up being the same string in there. [31:30.390 --> 31:32.690] Microsoft doesn't understand this notion. [31:32.950 --> 31:41.590] If you've got a password of love and it encrypts to whatever and John Doe has the password of love, you can just scream down visibly looking through and go, Oh, those two people have the same password. [31:41.910 --> 31:42.770] That's kind of hip. [31:44.090 --> 31:44.790] Next slide. [31:46.010 --> 31:47.970] So here we walk through what actually happens here. [31:48.610 --> 31:50.310] Two little A's becomes two big A's. [31:50.490 --> 31:52.730] You pad it out to 14 bytes, break it in half. [31:53.170 --> 31:55.210] String one is AA followed by five nulls. [31:55.310 --> 31:56.790] String two is seven nulls over here. [31:57.710 --> 31:58.630] Next slide, please. [32:00.530 --> 32:01.430] Standard DES stuff. [32:01.790 --> 32:03.510] Well, actually, the starter key isn't the DES. [32:03.650 --> 32:07.770] They lose some bits in there also, which is wrong. [32:08.550 --> 32:11.850] And then the standard DES stuff, they set up the key schedule. [32:12.270 --> 32:12.830] No problem. [32:12.930 --> 32:13.190] Next slide. [32:13.330 --> 32:15.350] We're just going to skip through some of the technical crap here. [32:15.930 --> 32:17.370] They encrypt it against the known constant. [32:17.450 --> 32:21.550] Now, the thing is, you saw that it was AA five nulls and then seven nulls on the other side. [32:21.550 --> 32:24.330] They encrypt both of those against the same damn constant. [32:26.470 --> 32:28.610] I'll let that sink in for a couple seconds here. [32:29.670 --> 32:30.910] This is stupid. [32:32.550 --> 32:38.930] Output two, the second string has this wonderful AAD3B435B51404EE. [32:39.070 --> 32:42.310] I'm going to get that tattooed across my forehead and walk down the halls of Microsoft. [32:49.120 --> 32:53.120] When you see this, this means that the user's password is seven characters or less. [32:53.540 --> 32:55.420] Okay, let's roll on to the next one. [32:55.420 --> 32:58.380] Actually, I should get their secret constant tattooed there. [33:00.240 --> 33:01.100] They concatenate it. [33:01.180 --> 33:04.080] And you can see the second half, which starts off AAD3B435. [33:04.260 --> 33:09.840] This is why you don't encrypt both sides with the same constant and then just concatenate them together. [33:11.780 --> 33:12.480] Next slide. [33:13.060 --> 33:13.380] All right. [33:13.780 --> 33:14.600] Why it's lame? [33:17.020 --> 33:18.600] Only 14 characters long. [33:19.780 --> 33:20.700] There's no salt. [33:21.440 --> 33:25.300] People with the same passwords are going to show up as the same crypt string, if you will. [33:26.020 --> 33:30.140] And in reality, it's not even the 14 characters long that you have to worry about. [33:30.540 --> 33:31.980] It's the seven characters. [33:33.560 --> 33:34.800] Hit the next slide, please. [33:35.700 --> 33:39.200] So, we said that they had two passwords stored inside the registry there. [33:39.360 --> 33:40.900] The LANMAN hash and the NT hash. [33:41.440 --> 33:44.180] The NT password can be up to 128 characters in length. [33:44.860 --> 33:45.880] Eh, that's a bit better. [33:46.060 --> 33:49.360] I'm not going to remember that password myself, but whatever. [33:49.920 --> 33:50.900] It's case sensitive. [33:51.260 --> 33:51.800] This is good. [33:53.280 --> 33:54.620] Passwords converted to Unicode. [33:54.720 --> 33:57.820] Unicode is this abomination of a representation of... [33:58.400 --> 34:06.720] Okay, if I have a byte 0x41, which happens to be a capital A, in Unicode, that's represented 0x41 0x00. [34:06.980 --> 34:17.680] So, I've doubled the length of it, but at least I can have support for character sets such as Kanji or other foreign character sets, which might need more than 256 bits to represent each individual letter. [34:18.160 --> 34:21.940] So, eh, don't know offhand if that's good or bad right here. [34:22.240 --> 34:22.820] Shouldn't be. [34:24.340 --> 34:27.300] Passwords then run through RSA's MD4 message digest function. [34:27.300 --> 34:30.560] And they take the resulting 16-byte value, and that's the NT hash. [34:30.900 --> 34:31.740] Well, that's cool. [34:32.040 --> 34:35.380] So, both of these guys are using strong crypto. [34:35.660 --> 34:37.420] The LANMAN and the MD4. [34:37.720 --> 34:41.220] They've got a... they've got DES under the LANMAN stuff. [34:41.440 --> 34:45.000] And they've got the message digest from RSA under the NT side of things. [34:45.340 --> 34:46.000] Not bad. [34:46.200 --> 34:50.500] This is just a brief run through of what happens for user 2A for the NT side of things. [34:52.740 --> 34:53.780] That's pretty straightforward. [34:53.940 --> 34:54.420] Next slide, please. [34:55.420 --> 34:56.700] So, what do we do with this? [34:57.220 --> 35:01.140] Well, we took a look at it and said, geez, this is really kind of lame. [35:01.300 --> 35:05.300] And once the deobfuscation was done, we could easily come up with a password cracker for it. [35:05.420 --> 35:07.140] You know, just run a standard dictionary on it. [35:07.760 --> 35:10.160] And some people said, wow, yeah, yeah, that's great. [35:10.300 --> 35:11.400] Microsoft said, oh, cool. [35:11.700 --> 35:17.220] And, you know, everybody said, you know, go back to sitting in your little room without the air conditioning and dinker a ray on your machine some more. [35:18.180 --> 35:19.280] So I went over to Weld. [35:19.880 --> 35:25.440] I said, Weld, look, this is really bad because we've got a couple of things in here that's just really going to knock them out of the water. [35:25.520 --> 35:30.320] And I'm going to show you how the LANMAN hash gets lamer and lamer and lamer and lamer here. [35:30.920 --> 35:32.340] But nobody's listening to me. [35:33.260 --> 35:35.240] Weld and I sat down and thought for a little bit. [35:36.640 --> 35:38.020] Weld said, you know what I'm going to do? [35:39.220 --> 35:40.560] I'm going to write a GUI for it. [35:42.620 --> 35:43.540] And we said, yeah. [35:49.460 --> 35:53.880] Because the thing is, everybody was going, oh, don't make a GUI out of an attack tool. [35:53.960 --> 35:55.960] Because then all the quote unquote script kiddies can run it. [35:56.440 --> 35:57.180] Well, guess what? [35:57.280 --> 36:00.600] Unless you make a point and click tool, the administrators don't know how to run it either. [36:06.760 --> 36:08.640] So we released this. [36:08.980 --> 36:10.200] Microsoft got a little bit upset. [36:10.200 --> 36:15.480] But they were more worried about some of the things we prophesized in the next version that we were coming out with. [36:15.840 --> 36:21.500] And inside here, this was version 1.0 that we came out with. [36:21.740 --> 36:26.380] And the brute force attack one, although the check box was there, didn't necessarily work in the GUI version. [36:26.500 --> 36:29.460] Which we shipped the command line version, which it did work with also. [36:30.280 --> 36:31.600] So hit the next slide. [36:32.420 --> 36:33.000] Thank you. [36:34.160 --> 36:36.060] So here's what we did in version 1.0. [36:36.060 --> 36:37.880] And of course, you know, the media loved it. [36:37.980 --> 36:40.300] Because all the newspaper people were like, ooh, pretty pictures. [36:43.880 --> 36:46.440] Crypt and compare dictionary attacks against the LANMAN hash. [36:46.660 --> 36:46.840] Great. [36:47.200 --> 36:49.340] Crypt and compare dictionary attacks against the NT hash. [36:49.540 --> 36:50.100] That's fine. [36:50.600 --> 37:03.220] Well, we decided that since you're storing the same password twice, just encrypted in different ways, and the LANMAN hash is much easier to actually break, you're reduced to the lowest common denominator for the amount of security that you hold with this encrypted password. [37:03.400 --> 37:08.400] So why don't we go after the LANMAN hash and then derive the NT hash off of it? [37:08.540 --> 37:20.180] Thus, if you have a password that ends up being seven A's long, alternating uppercase, lowercase, uppercase, lowercase, the LANMAN hash is going to automatically be converted to all uppercase. [37:20.740 --> 37:24.720] So we brute force through, end up hitting the seven uppercase letter A's. [37:24.880 --> 37:27.020] We then say, okay, this is seven A's. [37:27.080 --> 37:28.600] We don't know the case sensitivity of it. [37:29.180 --> 37:35.720] We will encrypt it with MD4, or hash it with MD4, and take a look if it matches. [37:35.820 --> 37:42.220] If it doesn't match, all we have to go through is two to the seventh number of possible combinations to get the case sensitivity out of it until it matches. [37:42.220 --> 37:50.180] So you break down to whatever is the easiest thing to go after, and the more complex things that are based upon it start to fall very quickly, too. [37:51.080 --> 37:56.620] The thing that really pissed Microsoft off was, because they were like, well, hey, you can dictionary attack UNIX. [37:56.820 --> 37:59.900] You can, hey, you can dictionary attack anything. [38:00.200 --> 38:10.400] And we said, yeah, but you're probably the only operating system that we've been able to see and implement a tool that lets you brute force through the entire key space of all the passwords. [38:10.400 --> 38:16.980] And what this means is, let's say you have a really, really, really good password that's not going to show up in a dictionary attack. [38:17.760 --> 38:18.560] It doesn't matter. [38:18.660 --> 38:19.260] It still gets it. [38:20.180 --> 38:22.400] All the way up to 14 characters long in length. [38:22.940 --> 38:24.060] And you said, well, that's cool. [38:24.060 --> 38:28.460] I could do the NT password, because that can be up to 128 characters long in length. [38:29.080 --> 38:32.100] Well, has anybody ever used the user manager tool inside NT? [38:33.120 --> 38:36.360] You know what happens when you start typing in past the 14th character? [38:37.040 --> 38:38.400] It starts beeping at you. [38:39.200 --> 38:41.680] It says, nah, nah, nah, 14 is good enough for you, Joe. [38:43.700 --> 38:44.440] Next slide, please. [38:46.360 --> 38:48.280] So here's how we basically approach the dictionary. [38:49.220 --> 38:50.840] Standard stuff, crypt and compare. [38:51.120 --> 38:53.260] It's nice to be able to talk to people who are somewhat familiar with this. [38:53.340 --> 38:55.720] I'm sure everybody in here has run crack at one time or another. [38:56.420 --> 38:57.280] This is what it does. [38:57.480 --> 39:02.540] We can instantly look through and throw away passwords longer than seven characters if we see the user password is less than. [39:03.660 --> 39:05.740] So we save some time running through the dictionary attack. [39:05.740 --> 39:08.680] We only have to run through one round of DES. [39:09.140 --> 39:11.140] UNIX is normally 24 rounds. [39:11.640 --> 39:12.840] So we've sped up there. [39:13.020 --> 39:14.740] And we don't have to deal with any of the salts. [39:15.300 --> 39:17.980] On UNIX, you'd have to run through 256 possible combinations. [39:18.380 --> 39:19.700] In this one, you run through one. [39:21.780 --> 39:26.060] And then what we do is once we get one, since there's no salts, we just scream down the rest of the user list. [39:26.460 --> 39:41.100] So if you have a user list of 1,000 people, and 50 of them have the password of welcome, and I encrypt welcome once, I just simply scroll down the list and see who fucking matched up with the encrypted string there, the hash. [39:41.100 --> 39:42.400] And it just starts popping in. [39:42.460 --> 39:43.820] Welcome, welcome, welcome, welcome, welcome, welcome, welcome. [39:44.020 --> 39:44.660] No more crypts. [39:44.720 --> 39:45.140] No more compare. [39:45.240 --> 39:46.580] Well, just compares at that point. [39:48.640 --> 39:53.380] We went to one installation and saw 700 users show up with the password of change me. [39:53.480 --> 39:54.720] We thought that was kind of humorous. [39:57.140 --> 39:59.260] This is called a large-scale NT installation. [40:00.040 --> 40:00.780] Next slide, please. [40:03.520 --> 40:07.740] NT and MD4, what we do here is we basically look for the LANMAN hash. [40:07.900 --> 40:13.520] Then we run a crypt and compare two to the sterling or whatever the dictionary word is to get the case sensitivity. [40:14.120 --> 40:16.060] Once we have that, we can hand it back to both of you. [40:16.820 --> 40:17.720] Why is this important? [40:18.360 --> 40:28.440] Well, if you don't know the case sensitivity and you walk up to the actual console and you know that an administrator's password is seven A's, but you don't know what's alternating uppercase, lowercase, uppercase, lowercase, you can't sit there and type it in and log in. [40:28.860 --> 40:31.500] You need to know the case sensitivity when you're sitting in front of the console. [40:34.260 --> 40:35.020] Next one, please. [40:41.950 --> 40:42.350] Dictionary. [40:42.350 --> 40:43.090] Yadda, yadda, yadda. [40:43.170 --> 40:43.490] Next, please. [40:44.950 --> 40:46.530] Okay, this is kind of interesting. [40:46.890 --> 40:49.230] Strongest password length in NT is seven characters. [40:50.690 --> 40:54.830] You have a ten-character long password, it's just as easy to break as a seven-character long password. [40:55.670 --> 40:59.130] You have a 13, 12, 11, whatever. [41:00.030 --> 41:05.170] The trick is, and obviously anything below seven characters takes less time to crack than seven characters. [41:05.690 --> 41:17.190] Since it breaks it into the two seven-part halves, the seven bytes, and it's encrypting it against the same string, if you want to brute force all the way up through it, and let's hit the next slide because I think we start talking about this. [41:18.090 --> 41:18.530] Yeah. [41:19.770 --> 41:21.570] User A just has a password of A. [41:21.930 --> 41:25.450] User, sorry, 7A has a password of, as you see. [41:25.970 --> 41:27.970] 10A has this password, so you've got seven and ten. [41:28.790 --> 41:29.850] There's the two hashes. [41:30.130 --> 41:36.650] You'll see this wonderful second half there, AAD3, B4, 3, 5, yadda, yadda, in the 7A one. [41:37.030 --> 41:41.030] And we know instantly that we don't have to ever compare the right-hand side of this hash. [41:42.130 --> 41:44.390] Bottom one with 10A doesn't have this problem. [41:44.910 --> 41:45.250] Next slide. [41:47.050 --> 41:47.890] So what do we do? [41:48.290 --> 41:50.450] Well, we take a little visual inspection on it. [41:50.530 --> 41:54.530] And we say, sure, user 7A is only seven characters long. [41:54.670 --> 41:55.970] User 10A has got to be more. [41:56.550 --> 42:05.430] So as we're running through, and we're just assuming a key space of just A's, we never have to check the right-hand side of user 10A until we get up. [42:06.250 --> 42:13.450] I'm sorry, we never have to check the left-hand side of user 10A on any passwords less than seven characters in length. [42:14.750 --> 42:17.810] And we only check the left-hand side of user 7A. [42:20.250 --> 42:20.810] Next slide. [42:20.950 --> 42:21.810] I think I've got this in here. [42:22.170 --> 42:22.230] Okay. [42:24.750 --> 42:27.530] Try AAA, yadda, yadda, yadda, yadda, yadda, yadda, yadda. [42:28.450 --> 42:28.810] Okay. [42:28.810 --> 42:38.390] When we get to the third AAA, and we're only checking the right-hand side of the user 10A password, we notice that it's three A's, because seven plus three is ten. [42:39.010 --> 42:43.430] Well, that was on our way up to seven anyway, because you're going to start at zero and move up to seven. [42:43.430 --> 42:48.130] By the time you've hit seven, you've got 14 total, because you're comparing both sides of it here. [42:48.390 --> 42:53.190] So we lock in on the second half of that second user that, oh, we know the second part is AAA. [42:53.710 --> 43:04.670] Now, those of you who are really motivated could take a dictionary attack and say, people with larger than seven character words, well, let's look into the right-hand side of it. [43:04.770 --> 43:13.550] If we latch in and see the last two words are ME, let's only stream through a dictionary that we have sitting elsewhere and look at words that only end in ME. [43:13.650 --> 43:17.890] We've instantly lopped out a tremendous amount of possibilities that we'd have to check. [43:18.750 --> 43:20.810] This would also work with pre-computing the hashes. [43:21.690 --> 43:22.530] Next slide, please. [43:25.450 --> 43:29.350] Once you get the LANMAN hash, you basically just derive the NT hash from it. [43:31.210 --> 43:40.350] Yet again, Microsoft kept saying, well, we aren't going to take responsibility for how lame LANMAN is, because that's the protocol that IBM came up with many years ago. [43:40.850 --> 43:41.870] We have to use it. [43:41.950 --> 43:42.670] We have it in there. [43:42.950 --> 43:43.210] Whatever. [43:43.470 --> 43:44.470] You know, hey, sue us. [43:45.390 --> 43:46.050] We'll win. [43:48.550 --> 43:52.390] So they have a... so they say, well, you know, if you're worried about security, use the NT dialect. [43:53.770 --> 43:57.510] Well, the NT dialect's strong, but you're sitting there with the LANMAN hash next to it. [43:58.270 --> 44:03.550] And the other thing is that you really need to be able to use the LANMAN hash, because how many of you work at a place that has... [44:03.550 --> 44:05.210] Well, let me raise the hands. [44:05.350 --> 44:10.530] How many people work or have been to a place that has Microsoft NT installed in like a commercial environment? [44:12.650 --> 44:13.810] Probably most of you. [44:14.010 --> 44:19.990] How many of you have been to that... have seen a place that has only NT installed? [44:20.190 --> 44:22.870] No 95, no Windows for work groups clients? [44:25.430 --> 44:27.130] You've been to a place that has nothing but NT? [44:27.690 --> 44:28.370] No 95? [44:29.270 --> 44:32.830] No UNIX running Samba or any... It's got UNIX there? [44:32.830 --> 44:34.370] All right, your hands disqualified. [44:34.810 --> 44:35.450] They could be. [44:35.610 --> 44:36.490] Oh, okay. [44:37.050 --> 44:40.770] That was one out of the army of hands that went up just a second ago. [44:42.710 --> 44:44.410] They can't get rid of this backwards compatibility. [44:44.430 --> 44:46.750] It's going to keep biting them on the ass for as long as they're around. [44:47.830 --> 44:48.750] Next slide, please. [44:51.530 --> 44:53.230] So what would you use L0phtCrack for? [44:53.430 --> 44:56.190] I'll let Well talk about this in a couple seconds. [44:56.270 --> 44:57.390] I just want to fly through here. [44:57.610 --> 44:58.830] And then we'll field some questions. [45:00.130 --> 45:01.770] Administrators could use it for auditing their systems. [45:01.770 --> 45:05.190] Currently, the way to check if a user has a good password or not on NT sucks. [45:05.470 --> 45:09.310] You have to turn off any security that you have so that you can keep trying to log in at that user. [45:09.510 --> 45:15.930] If you have lockout user after four or five tries and you run this, you're going to lock out all your user accounts and never know whether they had a good password or not. [45:16.230 --> 45:19.250] I think crack is a wonderful tool for both the bad guys and the good guys. [45:19.290 --> 45:20.750] Bad guys, again, being the corporations. [45:23.670 --> 45:25.850] So we said, oh, this is a useful tool. [45:25.870 --> 45:28.550] And it's easy enough to use that the administrators can figure it out too. [45:28.610 --> 45:28.890] Thank you. [45:30.150 --> 45:40.230] It's also important to realize that Microsoft is, I guess, Hobbit coined the wonderful term of the Microsoft Borg marketing juggernaut. [45:41.110 --> 45:45.210] They're just this huge, the Borg out of Star Trek, they're this huge race that just goes along. [45:45.390 --> 45:49.590] As long as you're not bothering them, they'll just kind of, like, consume everybody and pull them in as they need to. [45:49.670 --> 45:51.750] As soon as you get in their way, they try and, like, kill you off. [45:54.750 --> 45:55.070] Apple. [46:00.640 --> 46:02.680] And, of course, attackers could use this. [46:02.900 --> 46:07.800] Of course, with 1.0, you really had to be the administrator in order to dump the user passwords. [46:08.140 --> 46:13.740] If you were an administrator on a primary domain controller, though, you had everybody's passwords and you were guaranteed to be able to get back all of them. [46:14.520 --> 46:21.240] So it's not kind of like, geez, Microsoft came out with a message saying, don't choose stupid passwords that are easily guessable like dog and cat. [46:21.240 --> 46:28.260] Well, now we can say, don't choose passwords like A753216, bang ampersand, quote. [46:38.030 --> 46:38.890] Yeah, exactly. [46:39.110 --> 46:39.930] Microsoft's response. [46:40.410 --> 46:43.530] Even after we said that, they said, don't choose cat or dog. [46:44.310 --> 46:46.710] They also came out with this thing called the syskey patch. [46:46.990 --> 46:52.750] And what that did is it prevented the administrator from dumping out the registry to run the tool. [46:54.430 --> 46:55.050] Thanks, guys. [46:57.050 --> 46:58.310] They didn't stop the hackers. [46:58.510 --> 47:02.990] They said, oh, geez, if you stick your head in the sand, the problem goes away. [47:05.350 --> 47:10.850] So all they ended up doing is, I loved using the phrase emasculating in front of Microsoft employees. [47:12.210 --> 47:16.090] They never addressed the fact that their encryption was seriously, you know, like a big guffaw. [47:17.950 --> 47:22.370] So, of course, we had to have a response to Microsoft's response, because we felt a little slighted by this. [47:22.490 --> 47:27.550] So our response was, here's L0phtCrack version 1.5. [47:37.140 --> 47:41.400] Not only does the brute forcing work in the GUI, a whole bunch of holes were fixed up. [47:41.400 --> 47:47.520] Weld put in a really cool little hack, which was, I'll let him go into, like, all the functionality of the GUI and stuff. [47:48.200 --> 47:49.180] This was amazing. [47:49.580 --> 47:51.620] He kept getting on my butt to get things in gear. [47:51.740 --> 47:53.060] He was just flying on this. [47:55.060 --> 47:56.600] It does everything that 1.0 does. [47:56.760 --> 47:58.720] Some bug fixes, some serious speed improvements. [48:00.120 --> 48:05.640] And we said, well, geez, you know, they were bitching and moaning that, you know, you had to be administrator and so it wasn't an issue. [48:05.640 --> 48:10.880] And then they even released the Siski patch saying that even if you are administrator, you know, screw you. [48:11.040 --> 48:12.100] It's now doubly not an issue. [48:13.460 --> 48:14.820] Anybody ever heard of a sniffer? [48:17.460 --> 48:22.780] Yeah, you kind of watch those little passwords go by in the packet, because it's like an old party line phone system. [48:22.880 --> 48:26.620] You just, you know, aren't being nice and hanging up the phone when the call's not for you. [48:27.480 --> 48:28.140] Well, guess what? [48:28.220 --> 48:32.580] Microsoft has this challenge response mechanism that goes over the network that sends these passwords. [48:32.580 --> 48:35.480] But they knew, they knew their crypto was a joke. [48:35.820 --> 48:40.600] So they said, we are going to kind of turn these into a one way password. [48:40.800 --> 48:43.840] One way, a one way hash or one, I'm sorry, one time hash. [48:44.940 --> 48:49.760] So that if you catch it and try and play it back, we're going to give you a different challenge and it's not going to let you in. [48:52.120 --> 48:55.500] Well, we decided that we needed to break that also, so we did. [48:59.870 --> 49:00.450] Next slide. [49:02.050 --> 49:03.890] Here's how that challenge response works. [49:04.010 --> 49:07.390] Now remember, keep all of this in mind and see when this starts to sound familiar. [49:07.950 --> 49:12.370] Microsoft said, don't blame us for the LANMAN hash, it was IBM's fault. [49:13.370 --> 49:18.350] Use the Microsoft NT hash or whatever, which is just somebody else's stuff that we used anyway. [49:20.690 --> 49:23.910] Now look at what they do on the network side of things on their own. [49:25.970 --> 49:29.150] Client requests a log on challenge, server sends back an 8-byte challenge. [49:29.610 --> 49:32.850] So the client says, hi, I'd like to start talking to you, open up a session. [49:33.610 --> 49:38.950] The server says, here's 8 bytes worth of quote-unquote random. [49:39.910 --> 49:40.430] Right. [49:41.690 --> 49:43.330] Sorry, I'm laughing at random. [49:43.610 --> 49:47.150] Microsoft's idea of random is about 20 years behind the time. [49:48.510 --> 49:55.350] So the client takes it and desencrypts the LANMAN and NT dialect hashes with that 8-byte challenge and sends them back to the server. [49:55.470 --> 49:59.810] Server does the exact inverse to see if the hashes are the real user's password. [50:00.010 --> 50:02.390] So you don't have the actual hashes going across the network. [50:03.350 --> 50:03.890] Next slide, please. [50:06.530 --> 50:06.910] Okay. [50:07.810 --> 50:12.950] First thing they do is, they take that 16-byte hash, because the NT hash was 16 bytes and so was the LANMAN one. [50:12.950 --> 50:14.390] They pad it out to 21. [50:15.170 --> 50:17.290] Guess what 21 is divisible by? [50:17.730 --> 50:18.130] Three. [50:18.770 --> 50:23.510] You get seven groupings, or three groupings of seven characters. [50:24.170 --> 50:26.390] Geez, seven seems like a popular number over there. [50:26.690 --> 50:31.690] You take each of these 7-byte values and derive three 8-byte odd parity DES keys. [50:33.410 --> 50:43.230] Now, when Microsoft had the chance to do it themselves and prove that they knew that LANMAN was a lame way of sending across their different hashes, including their NT one, they did it based upon the LANMAN model. [50:45.030 --> 50:45.750] Next slide, please. [50:49.130 --> 50:49.710] Let's see. [50:49.870 --> 50:55.650] It encrypts the same 8-byte challenge with each one of the key schedules derived there. [50:55.830 --> 50:59.950] This is the same as taking their secret constant and re-encrypting the first half and second half. [51:00.050 --> 51:04.090] This time they're taking this one same value and encrypting the first half, the second half, and the third half. [51:04.390 --> 51:05.330] Third half, whatever. [51:06.170 --> 51:07.690] Geez, I sound like a Microsoft drone. [51:09.490 --> 51:11.670] This response is then sent back to the server. [51:12.030 --> 51:13.770] Same thing is done for the MD4 hash. [51:14.770 --> 51:15.310] Next slide, please. [51:16.890 --> 51:17.910] It's just an example. [51:18.330 --> 51:19.150] We'll spin through. [51:21.070 --> 51:21.590] Yep. [51:22.390 --> 51:22.650] Yep. [51:25.670 --> 51:26.190] Okay. [51:27.010 --> 51:27.810] There we go. [51:28.330 --> 51:32.490] So 1.5 does the same dictionary hash, dictionary attack on this network stuff. [51:34.890 --> 51:39.370] All we end up doing is padding it up to 21 bytes, taking the challenge of response and encrypting it there. [51:40.190 --> 51:41.070] Next slide, please. [51:42.670 --> 51:43.510] Now, here's the problem. [51:43.710 --> 51:45.190] You can brute force this also. [51:46.350 --> 51:53.190] So all you have to do is sit on the goddamn network, watch them go back and forth with the syskey patch, and the only person who can't check the passwords is the administrator. [51:58.120 --> 52:12.240] What we do is we take the last two bytes of the LM hash, and that ends up being 040z, 040e, append five nulls to that, and we can quickly see if the password was seven characters or less. [52:12.940 --> 52:14.980] Well, now we've instantly dropped things down. [52:17.980 --> 52:20.680] We encrypt that against the 8 byte challenge. [52:20.900 --> 52:24.060] If it matches, there was a pretty good chance that it was seven characters or less. [52:24.240 --> 52:29.760] We can very easily run through enough permutations to guarantee that it was or was not. [52:30.800 --> 52:31.300] Next slide. [52:33.560 --> 52:35.160] God, it's been a little bit since I've looked at this. [52:35.360 --> 52:36.880] I hate looking at Microsoft stuff. [52:41.250 --> 52:46.470] Yeah, we have to run through 356 tries to figure out if it was under eight characters. [52:47.610 --> 52:51.890] I'm just going to spin on, because I want to let Weld go into the GUI. [52:55.030 --> 52:58.750] Oh, one of the things we made sure we did is we gave out source code to this with it. [52:59.470 --> 53:04.090] If some of this isn't making any sense, we always try and make sure that you have the source code. [53:04.250 --> 53:07.370] If you think it needs to go faster, there's plenty of room for optimizations. [53:07.370 --> 53:12.310] If you think it needs to have extra functionality in it, you have the source code. [53:12.730 --> 53:14.370] Go ahead, hack it the hell up. [53:14.470 --> 53:15.270] That's what it's there for. [53:15.390 --> 53:16.050] See how it works. [53:16.170 --> 53:18.950] See how Microsoft is doing some of this shit that they're shoving down your throats. [53:20.410 --> 53:24.330] One thing I ask, though, if you add cool things into it, send us back the diffs. [53:24.650 --> 53:27.010] We'd love to pull them back into the next versions and everything. [53:27.050 --> 53:28.130] No problem giving credit. [53:28.850 --> 53:29.750] It just goes out. [53:29.870 --> 53:30.350] This is free. [53:30.470 --> 53:31.510] This is for people to use. [53:32.990 --> 53:37.870] I'm going to just basically skip on how it does the challenge response right now because I know we're pushing time. [53:38.570 --> 53:39.650] Everybody's got to sit around here. [53:41.170 --> 53:41.530] Oh, yeah. [53:41.810 --> 53:47.030] The other thing was, they said, well, just use the NT hash in their service pack 3. [53:47.370 --> 53:49.790] They said, oh, well, just use the NT. [53:50.010 --> 53:51.070] Just authenticate on the NT. [53:51.070 --> 53:55.030] They still sent the LANMAN hash across the network anyway, which made that brute forceable. [53:56.550 --> 53:57.110] Next. [53:58.970 --> 54:02.070] So we're still threatening Microsoft with the version 2.0. [54:03.530 --> 54:07.950] The PDC, BDC backup and syncing looks really atrocious. [54:09.870 --> 54:14.070] You can basically hop on the network and say, I'm the BDC now. [54:14.790 --> 54:15.930] They all believe you. [54:16.110 --> 54:17.010] It's no problem. [54:22.610 --> 54:24.430] We've got the sniffer up. [54:24.590 --> 54:28.730] I don't think we've actually put it up on the website yet just because I'm still putzing around with it. [54:28.950 --> 54:32.910] We want to develop a Windows NT one so the people who don't necessarily have UNIX can have that running also. [54:33.670 --> 54:47.290] At a conference, Microsoft promised me in front of other witnesses that they would give the L0pht a copy of the DDK, the device developers, device drivers kit, whatever the hell the acronym stands for, to show how they do the packet filters. [54:47.290 --> 54:49.470] Yeah, like we've seen that from them. [54:50.710 --> 54:57.450] And we're going to throw in a bunch of passive mode components which attack the network by listening to how chatty the Microsoft machines are. [54:57.670 --> 55:01.710] An example of this is how Microsoft machines basically come on the net and tell you who you are. [55:02.490 --> 55:08.430] If a Microsoft machine comes on, it'll say, hey, I'm machine number, I'm machine foobar. [55:08.990 --> 55:09.770] Everybody cool with that? [55:09.830 --> 55:13.390] And somebody else comes back and says, no, I'm foobar. [55:13.390 --> 55:14.330] Oh, okay, okay. [55:14.950 --> 55:15.790] I'm foobar too. [55:16.050 --> 55:16.330] Anybody? [55:16.650 --> 55:16.810] Anybody? [55:17.850 --> 55:18.590] All right, that's me. [55:18.750 --> 55:19.030] That's right. [55:19.410 --> 55:19.990] Here I am. [55:20.830 --> 55:22.490] This is how they do all their stuff. [55:22.590 --> 55:24.430] It's whoever shouts the loudest on the network. [55:25.770 --> 55:35.030] If you're a big UNIX house or whatever, and you put a sniffer on the line and two days later you throw NT on there, you will be amazed at how much crap is bouncing back and forth. [55:35.950 --> 55:40.470] And we're going to have enough components in there that we should be able to release the L0pht disk service pack. [55:48.850 --> 55:54.010] Because one of the things that somebody came up to me recently and they said, yeah, we've got NT. [55:55.090 --> 55:56.450] I don't know if it's vulnerable or not. [55:56.630 --> 55:58.810] If you broke into it, why would you want to? [55:58.910 --> 56:00.210] What can you do on it? [56:01.630 --> 56:06.710] So I looked at them and I said, if that's the case, why are you using it? [56:09.570 --> 56:11.410] They said, well, it's not like you can get a shell prompt. [56:11.970 --> 56:12.670] Yeah, right. [56:12.990 --> 56:21.690] So I showed them the telnet daemon that we wrote that we end up like throwing on the boxes and it hands back a nice little c colon backslash, you know, MS DOS, yada, yada, yada. [56:21.830 --> 56:23.650] Now you're sitting locally on the machine over the network. [56:24.750 --> 56:25.710] They didn't like that. [56:27.290 --> 56:27.830] Next slide. [56:28.010 --> 56:28.610] I think that's it. [56:28.990 --> 56:29.350] Great. [56:29.470 --> 56:36.070] So before we go on, I want to hand this over because I've gone around giving lots of talks about how Microsoft actually does this stuff underneath. [56:36.370 --> 56:46.590] I did none of the GUI coding because that is really our GUI whiz here who just walks over and thunks me on the back of the head once in a while going, this is how Microsoft really works. [56:47.090 --> 56:49.470] I'm going to hand it over to Will Pond for any comments and everything. [57:03.540 --> 57:06.660] I just have a couple of things to say because much covered most of it. [57:06.800 --> 57:22.340] But I knew L0phtCrack was becoming a popular tool when the sysadmin of the company I'm working for, who knows nothing about me being the author, came to me and said, you know, I'm running L0phtCrack on our password database and everyone's got the same password as our company name. [57:23.340 --> 57:27.120] So I knew there were a lot of people out there using it. [57:29.700 --> 57:46.440] One thing Mudge didn't mention was the response that Microsoft had for our L0phtCrack 1.5 release, which had great timing because it came out exactly one day after he gave his black hat talk, basically releasing 1.5 and talking about what his capabilities were. [57:47.120 --> 57:54.740] And their hotfix, which is probably going to be in their service pack 4, was... [57:56.240 --> 58:05.920] Yeah, they have the hotfix out, which is to turn off LANMAN authentication over the network for NT workstations or servers. [58:06.220 --> 58:11.860] Basically does absolutely nothing for Windows 95 users or, you know, backwards compatibility. [58:11.880 --> 58:13.740] So they really haven't fixed the problem. [58:13.860 --> 58:15.220] They pretend they fixed the problem. [58:16.320 --> 58:22.800] There was an article in Network World last week, which Mudge is quoted in. [58:23.360 --> 58:27.860] And basically the slant of the article was, Microsoft, you didn't fix the problem. [58:28.920 --> 58:29.440] So... [58:29.440 --> 58:36.040] Remember the people who raised their hands saying that we have both Windows 95 and NT in our office and everything? [58:36.920 --> 58:40.700] And Microsoft came out with the LM fix or LM whatever to stop sending it? [58:40.840 --> 58:42.260] You can't use it. [58:42.780 --> 58:43.780] It's only for NT. [58:44.040 --> 58:49.140] So their response is, pay a couple hundred dollars for a workstation if you want security. [58:49.240 --> 58:51.060] That's how we fix our operating system. [58:52.820 --> 58:56.020] And I guess we can open up for questions now for anybody. [58:56.340 --> 58:58.660] Well, mention the multiprocessor version. [58:58.860 --> 58:59.420] Is that in the works? [59:00.020 --> 59:02.460] Yeah, well in the works is the multiprocessor version. [59:03.620 --> 59:06.540] If I can find a Quad Pentium Pro that someone wants to donate. [59:06.680 --> 59:07.140] No, not really. [59:07.280 --> 59:09.220] But I have some access to some. [59:09.420 --> 59:10.620] So I'm working on that right now. [59:12.960 --> 59:21.000] With that, I think we're going to try and make Emmanuel jump around a little bit as we go like five more minutes over, which we're actually right on time right now. [59:21.220 --> 59:24.480] And give people an opportunity to answer... to answer. [59:24.620 --> 59:25.620] We'll ask you the questions. [59:25.720 --> 59:25.800] Quickly. [59:26.360 --> 59:28.660] To ask a couple questions of anybody on the panel. [59:29.360 --> 59:31.380] If there are any questions to be asked. [59:33.300 --> 59:33.740] Questions? [59:34.380 --> 59:38.140] I'd love to ask some questions about NDS, since that's where I come from. [59:38.260 --> 59:40.860] And I'll talk to you about that offline, because no one cares about it. [59:42.020 --> 59:51.420] On the NT side, when you release your NT sniffer, would you please allow it to save directly to disk? [59:51.680 --> 59:58.340] I've got a network general sniffer, and I have to keep recycling my traces so fast, because our network is so busy. [59:58.560 --> 01:00:00.500] I would love to just write directly. [01:00:00.620 --> 01:00:01.260] Can you do that? [01:00:01.260 --> 01:00:08.420] Yeah, the sniffer that's coming out, we're going to just release basically one that works on UNIX first. [01:00:09.640 --> 01:00:17.580] It's easier, and we're just attaching the libpcap or bpf or devnet or whatever you want, and key into the SMB packets going back and forth. [01:00:18.040 --> 01:00:27.320] I don't know exactly when the Microsoft-based one is going to come out, because they're not being very helpful, since we don't have any money and all we're doing is being a pain in their ass. [01:00:28.460 --> 01:00:30.440] They're not giving us any help writing it, obviously. [01:00:31.740 --> 01:00:35.020] But yes, you'll be able to save the disk, dump directly to standard out. [01:00:35.900 --> 01:00:46.560] Maybe we'll even throw it in the sniffer by itself, or the loss track on itself, so if you're bored, you just set the thing up to run at night when you go home, and it listens to the network and cracks them at the same time. [01:00:54.430 --> 01:00:56.070] I have a question for the hardware side. [01:00:57.150 --> 01:01:02.090] As for the PalmPolots, have you been able to hack into the chip to get greater storage capacity? [01:01:03.210 --> 01:01:04.950] Can you try that again. [01:01:05.350 --> 01:01:08.650] Have you been able to hack the chip to get greater storage capacity? [01:01:10.330 --> 01:01:10.730] Yeah. [01:01:11.550 --> 01:01:12.110] Yeah. [01:01:13.650 --> 01:01:20.310] On the back of this, the RAM and ROM modules are removable just to make the whole system modular. [01:01:20.730 --> 01:01:22.910] And that's where you upgrade the OS from there. [01:01:23.130 --> 01:01:26.610] And there's a couple pads that chips aren't in yet. [01:01:26.790 --> 01:01:37.250] So you can basically just solder surface mount chips on and probably get like, I think it's two megs without any additional hardware except the RAM itself. [01:01:37.250 --> 01:01:39.870] Yeah, there's actually a company out there that does that already. [01:01:40.230 --> 01:01:41.730] But you can do it yourself for cheaper. [01:01:42.130 --> 01:01:46.930] What about the three meg upgrade they have now with the flash memory? [01:01:48.070 --> 01:01:55.490] Yeah, they upgrade the flash, the SRAM chips, so you can load a larger Palm OS on it. [01:01:56.010 --> 01:02:06.370] And I know there's one memory module that I think allows you to put a, I think it's a DS, no, it's a pseudo DRAM, I think. [01:02:07.030 --> 01:02:09.070] And it's like an SRAM, but it's a DRAM. [01:02:09.150 --> 01:02:10.590] It's got the refresh built onto it. [01:02:12.290 --> 01:02:14.070] You can also buy that from this. [01:02:14.170 --> 01:02:15.430] There's a company on the web, actually. [01:02:15.490 --> 01:02:17.490] If you do a search, you'll find it. [01:02:25.750 --> 01:02:31.250] I was just wondering if the PowerPoint slideshow is available on your website or if you're planning on making it available. [01:02:34.010 --> 01:02:36.570] It's not up there right now, but that's a good point. [01:02:37.770 --> 01:02:41.570] If PowerPoint has some easy way, I am like the worst web person in the world. [01:02:41.870 --> 01:02:47.710] If PowerPoint has an easy way to export out into HTML or maybe I'll just dump it out into GIFs or Postscript or whatever, I'll do that. [01:02:48.050 --> 01:02:48.770] No problem. [01:02:51.110 --> 01:02:54.070] Yeah, I don't run NT or a Microsoft product. [01:02:54.210 --> 01:02:57.410] So A, I have to find somebody else's machine that has it on there. [01:02:57.950 --> 01:02:59.310] No, I'll do that. [01:02:59.370 --> 01:03:01.930] I'll try and get that up within the next week. [01:03:03.330 --> 01:03:19.590] In regards to a site that was running IIS as a web server, if they decided to use NT security to secure their pages, could a version of L0phtCrack be set up to do remote attacks using the challenge response that the web server would set up? [01:03:26.370 --> 01:03:37.190] Well, I believe the same challenge response that goes over the, for the, if you're on the, if you're just attaching to a file share, it's the same challenge response mechanism. [01:03:37.190 --> 01:03:40.910] So if you can capture that, you should be able to use L0phtCrack on it. [01:03:41.290 --> 01:03:41.490] Okay. [01:03:43.530 --> 01:03:44.930] All right, that's... [01:03:45.590 --> 01:03:52.310] I have to ask, because I know UNIX can be brute force cracked, but the worst case scenario is like 30,000 years to crack a password. [01:03:52.310 --> 01:03:55.950] So I'm just curious for comparison how long L0phtCrack will take. [01:03:56.170 --> 01:04:00.350] Well, I have access... you're going to talk about the intel way of doing this. [01:04:00.490 --> 01:04:01.610] I'll talk about the other architecture. [01:04:02.930 --> 01:04:12.370] The first time I ran Pete's, you know, prototype code, I was sort of like floored by how quickly it happened, just for the reasons he was talking about. [01:04:12.470 --> 01:04:21.310] No salt, one round of DES, and, you know, the password being split into two halves, so seven is the maximum. [01:04:21.310 --> 01:04:27.950] Basically, you know, over time we did a little bit of optimization and I did some benchmarking. [01:04:28.250 --> 01:04:33.470] And this is running on intel hardware, which much tells me it's a lot quicker on... [01:04:33.470 --> 01:04:36.290] If you run it on an Ultra Spark with 64-bit. [01:04:36.530 --> 01:04:41.510] But dictionary attacks, generally, you could dictionary attack with a... [01:04:41.510 --> 01:04:47.430] I was using a 28,000 word dictionary on 100 users on a Pentium Pro 200 under a minute. [01:04:48.970 --> 01:04:50.090] Brute forcing... [01:04:51.310 --> 01:04:53.870] Brute forcing depends on the character set. [01:04:54.170 --> 01:04:56.050] This is something I just didn't talk about too much. [01:04:56.390 --> 01:05:07.970] But if you just do alphanumeric and you don't throw in punctuation characters, you can brute force on a Pentium Pro 200 through the whole key space in about a day. [01:05:09.410 --> 01:05:19.290] If you throw in punctuation characters, which is a good thing to do if you are worried about your password being secure against brute force, is to up the key space. [01:05:19.710 --> 01:05:25.130] And if you use punctuation, you're making it so that... [01:05:26.610 --> 01:05:34.770] Even with L0phtCrack, if you use some funky punctuation characters, you can make a password that would take a few hundred days to crack. [01:05:35.270 --> 01:05:37.410] But not many people remember those things. [01:05:37.970 --> 01:05:42.630] So, you know, tell your administrator to throw in an ampersand. [01:05:43.890 --> 01:05:51.030] That's a few hundred days, which is still less than a year to go through the entire key space, which is a tremendous difference. [01:05:51.030 --> 01:06:03.650] The other thing is, while Weld was working on the Intel side of things, I was playing over on the UltraSpark side of things, which I really think if anybody is into fast breaking and encrypts and moves and stuff, go get an UltraSpark. [01:06:03.770 --> 01:06:04.950] It's the best bang for the buck. [01:06:05.270 --> 01:06:13.230] Turn on all the optimization, make it so it's not portable code, and that hundred days or so drops down to about 20. [01:06:17.740 --> 01:06:19.580] All right, that's all the questions. [01:06:19.700 --> 01:06:21.040] I'd like to thank everybody here. [01:06:21.040 --> 01:06:30.240] We've got somebody, hold on, we've got an amazing treat for you, which is Bruce Schneier, author of Applied Cryptography, is [01:06:34.960 --> 01:06:36.140] going to be talking next. [01:06:37.200 --> 01:06:40.140] So, without further ado, I don't know a better way to introduce this man. [01:06:40.160 --> 01:06:41.340] His name says it all. [01:06:41.540 --> 01:06:43.420] Here is Mr. Bruce Schneier. [01:06:54.280 --> 01:06:54.680] Stupendous. [01:06:54.680 --> 01:06:54.760] Thank you very much.